Описание
In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.
Ссылки
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:aimstack:aim:3.22.0:*:*:*:*:python:*:*
EPSS
Процентиль: 59%
0.00384
Низкий
7.5 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 59%
0.00384
Низкий
7.5 High
CVSS3
Дефекты
CWE-22